Search by job, company or skills

Yahoo Taiwan E-Commerce

(Sr.) Technical Security Engineer

new job description bg glownew job description bg glownew job description bg svg
  • Posted 9 hours ago
  • Be among the first 10 applicants
Early Applicant

Job Description

With millions of users relying on us, we are a high-profile target for adversaries across all levels of our tech stack. Our mission is to protect our users and make our platform one of the safest places to shop online in Taiwan.

We are looking for a Security Engineer responsible for cloud security, SDLC security, and security planning for TWEC.

Responsibilities

  • Collaborate on secure software development processes, including defining security requirements, reviewing software architecture, reviewing code and providing vulnerability consultation.
  • Conduct web security assessments and ensure compliance with standards such as PCI DSS.
  • Develop and maintain scalable strategies and policies to secure TWEC's public cloud platforms.
  • Drive company-wide adoption of cloud and compute security policies.
  • Design and implement enhancements to identify security misconfigurations accurately. Conduct thorough security reviews and provide project consultation.
  • Evaluate and manage vulnerabilities across cloud environments, prioritize remediation efforts, and ensure continuous monitoring of potential threats.
  • Monitor, evaluate, and respond to security alerts and events. Handle and analyze incidents to support effective resolution.
  • Identify security risks and recommend improvement plans to enhance resilience.

Minimum Qualifications

  • BS/MS in a Science/Technology/Engineering/Mathematics related field or equivalent experience
  • 3+ years of related experience
  • Experience with application programming or devops and the overall software development life cycle
  • Good knowledge of web security vulns and countermeasures, including the OWASP Top10.
  • Familiarity with the security features and best practices of major cloud platforms, such as AWS and GCP.
  • Good communication and collaboration skills to work with people from a variety of technical backgrounds

Preferred Qualification

  • Good Knowledge of container and cloud infrastructure security concepts.
  • Good knowledge and hands on practice of Java, PHP, python or shell script.
  • Proficient in Linux and Windows server security management.
  • Knowledge or experience with a broad array of security technologies, such as Firewall, WAF, SIEM, Endpoint Security and more.
  • A personal commitment to continuous learning and self-development.

More Info

Job Type:
Industry:
Employment Type:

Job ID: 135895893